SC-100 Practice Question: Design security solutions for applications and data
Trey Research, a biotech firm, is developing a machine learning model on Azure Machine Learning that uses sensitive genomic data. The data is stored in Azure Blob Storage. The company requires that all data be encrypted at rest using customer-managed keys stored in Azure Key Vault, and that access to the storage account be restricted to the Azure Machine Learning workspace and specific data scientists via Microsoft Entra ID authentication. Additionally, the storage account must be accessible only from the company's virtual network. Which of the following configurations should you implement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable encryption at rest with a customer-managed key, configure a private endpoint for the storage account, and grant the Machine Learning workspace and data scientists access using Azure RBAC with the Storage Blob Data Contributor role.
It provides encryption at rest with a customer-managed key (CMK) stored in Azure Key Vault, a private endpoint to restrict access to the company's virtual network, and Azure RBAC with the Storage Blob Data Contributor role for both the Machine Learning workspace and data scientists, ensuring Microsoft Entra ID authentication. Option A is wrong because firewall rules using IP ranges are less secure than private endpoints, and granting access via storage account access keys bypasses Microsoft Entra ID authentication. Option B is wrong because it uses a service-managed key, which does not meet the customer-managed key requirement. Option D is wrong because a service endpoint is less secure than a private endpoint, and using a SAS token does not provide Microsoft Entra ID-based access control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable encryption at rest with a customer-managed key, configure a firewall to allow the Machine Learning workspace's IP range, and grant data scientists access via storage account access keys.
Why it's wrong here
Storage account access keys are shared secrets, so they bypass the Microsoft Entra ID authentication requirement entirely. IP-range firewall rules are tempting because they restrict traffic to known addresses, but they cannot confine access to the workspace's virtual network as the scenario demands.
- ✗
Enable encryption at rest with a service-managed key, configure a private endpoint, and grant data scientists access using Azure RBAC with the Storage Blob Data Reader role.
Why it's wrong here
Service-managed keys are generated and rotated by Microsoft, so they fail the explicit customer-managed key requirement held in Azure Key Vault. Private endpoints are tempting because they restrict storage access to the virtual network, which is exactly the correct choice when CMK encryption is not mandated.
- ✓
Enable encryption at rest with a customer-managed key, configure a private endpoint for the storage account, and grant the Machine Learning workspace and data scientists access using Azure RBAC with the Storage Blob Data Contributor role.
Why this is correct
Customer-managed keys in Key Vault satisfy the encryption-at-rest requirement, the private endpoint restricts the storage account to the virtual network, and Azure RBAC with Storage Blob Data Contributor grants least-privilege access via Microsoft Entra ID. Together these meet all three stated constraints.
- ✗
Enable encryption at rest with a customer-managed key, configure a service endpoint for the storage account, and grant the Machine Learning workspace access using a SAS token.
Why it's wrong here
A SAS token is a shared secret, not an Microsoft Entra ID identity, so it cannot satisfy the requirement that access be restricted via Microsoft Entra ID authentication. Service endpoints are tempting because they secure traffic to the storage account from a subnet, but they do not enforce identity-based authorisation.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.